AllowOverride

AllowOverride and the Override Classes

AllowOverride names the directive classes .htaccess files below its <Directory> may use. It has defaulted to None since 2.4; with AllowOverrideList also None, the file is never opened. "Here" counts what apache2ctl -L reports for this server's 32 modules. Any value but None also allows 23 class-free directives such as <IfModule>, <Files> and <If>.

AllowOverride values and the directives they unlock
Value Here Unlocks, for example
AuthConfig 15 AuthType, Require
FileInfo 53 Header, Rewrite*, Redirect*
Indexes 24 DirectoryIndex, Expires*
Limit 3 Order, Allow, Deny (legacy)
Options[=list] 8 Options, php_value
Nonfatal=... - Skip bad lines, log a warning
All 128 Every class above

A forbidden directive fails the whole request. DirectoryIndex home.html plus Header set X-Frame-Options "DENY" returns 500 under AllowOverride AuthConfig Indexes:

Output of 29
[core:alert] ... /var/www/example/.htaccess: Header not allowed here

Typos fail the same way (Invalid command 'DirectoryIndx'). Adding Nonfatal=Override returns 200 without the header and logs warning AH02295, but a skipped Require would leave a folder open. Options=Indexes limits only what a file may switch on; a bare Options Indexes still switches the other inherited options off. And configtest passes AllowOverride inside <DirectoryMatch> or <Location>, yet both were silently ignored here, with no lookups in strace.